Currently dealing with a breach or active incident?Call 406-924-3731×
≡
HIPAA programs — Great Falls, Billings, Helena and across Montana

HIPAA evidence you could hand to an auditor tomorrow.

HIPAA compliance as a service for Montana practices and the vendors who serve them.

A current Security Risk Analysis, the policies and training records behind it, and a fix list your IT team can work from maintained year round instead of rebuilt when someone asks.

★★★★★5.0 on Google and Birdeye.Read the reviews
A nurse greeting a patient
$350
Starting at per month
30 min
Gap review call
Annually
Risk analysis refreshed
and on material changes
Since 2013
Our team serving Montana
supporting businesses and nonprofits across the state
Start here

Which one are you?

Two different obligations. Pick the one that describes you and the rest of the page follows.

Covered entity
You treat patients
Practice, clinic, dental, behavioral health, specialty group.
This is you if
—A patient could file a complaint about you
—A payer or hospital sends you questionnaires
—Your name is on the breach notice
What this means for practices →
Business associate
You serve people who treat patients
Billing, IT, software, medical devices, marketing, and answering services.
This is you if
—PHI passes through your systems
—Your clients are asking you for evidence
—You are liable in your own right, not through them
What this means for vendors →
Not sure? If protected health information passes through your systems and you are not the one treating the patient, you are almost certainly a business associate.
Why you are here

Most people arrive holding one of these.

An outside party is asking
—A payer, hospital or health system sent a security questionnaire and you can't answer half of it
—A client is looking to end the contract unless you can prove your security posture
A deadline is attached
—Your cyber insurance renewal asks whether you've completed a risk analysis in the last 12 months
—You attested to a Security Risk Analysis for MIPS and quietly hoped nobody would check
Something happened nearby
—A practice nearby got hit with ransomware and your partners started asking questions
—You inherited a binder from a consultant and nothing in it has changed since
The four answers we hear

You have probably been told it's taken care of.

One of these is usually the reason. The middle column is the short version; the right is why.

What we hear
The short answer
Why
“We had a scan run.”
A scan is not a risk analysis.
A scan finds technical weaknesses. The SRA is a written assessment across administrative, physical and technical safeguards — policies, staff, front desk, vendors, building. Producing a scan when an investigator asks for a risk analysis is handing over a receipt when someone asked for the tax return.
“Our EHR is HIPAA compliant.”
Their platform, not your practice.
It says nothing about your workstations, Wi-Fi, staff, other vendors, remote access or physical office. Most of what gets examined in an investigation is not in the EHR at all.
“Our IT company handles it.”
Ask for two documents.
The risk analysis, and training records with names and dates. If both exist and are current, you are in better shape than most and may not need us. Most managed IT contracts cover uptime and tooling, not evidence.
“We did one when we opened.”
It expires in practice.
The Security Rule requires the analysis to be current and updated on material change. New staff, new software, a new location, a new vendor — an analysis from three system changes ago describes a practice that no longer exists.
If any of those sounded like your practice, the gap review is thirty minutes and will tell you exactly where you stand.
What we find

Ranked by how often we find it.

Typical findings in the order they show up. The first is the one that becomes a reportable breach without anyone visiting your building.

01
Patient data or systems reachable from the internet
Remote access left open for a vendor and never closed. A server exposed during a migration. A share or portal never meant to face outward. Findable by anyone scanning the internet.
Most frequent
02
No current risk analysis
It's the most common finding in the practices we assess. Several never have.
Very common
03
BAAs missing or expired
Usually for vendors nobody realised touch PHI: the shredding company, the answering service, the marketing agency with the patient list, the IT provider itself.
Common
04
Training records that do not exist
Often in practices where the training genuinely happened. Under investigation, training you cannot prove is training you did not do.
Common
05
Backups never tested with a restore
A backup you have never restored from is a plan, not a capability — and it is the difference between a bad week and a closed practice during ransomware.
Seen regularly
Frequency is a relative scale across the assessments we have run, not a published statistic.
How it runs

Assess, plan, maintain, respond.

Four phases to the HIPAA program. The third is the one that matters most, because it stops this being a project that starts and stops.

01Assess
Weeks 1–2
Risk analysis across administrative, physical and technical safeguards. Every device, system and vendor that touches PHI, plus external exposure testing.
You get
Written findings, ranked by risk
02Plan
Week 3
Every finding becomes a dated, owned, prioritized task. Not “improve access controls” — which system, which setting, which order, and what it protects.
You get
A fix list your IT team can run
03Maintain
Ongoing
Analysis refreshed annually and on material change. Policies matched to how you operate. Training tracked by name. BAAs calendared with renewal dates.
You get
A single page status, any time
04Respond
When it lands
The questionnaire, the renewal application, the payer audit or the incident. You forward it to us.
You get
Someone else writes the answer
Who does the fixing? Your IT team in most cases, which is why the plan is written to be executed rather than admired. If you would rather we did it, we scope and quote separately we do not bury remediation hours in a monthly fee and we do not hold the fix list hostage to buying it from us.
The evidence file

What you can physically hand someone.

The test that matters: if a payer, an investigator, an insurer or an acquiring practice asked today, could you produce these within an hour?

✓Security Risk Analysis, dated within 12 months, with stated methodology
✓Risk management plan: what you fixed, when, and what is still open
✓Written policies and procedures matched to your systems, including the sanction policy
✓Workforce training records with names, dates and completion
✓Asset and data inventory: every system and device that touches PHI
Could you produce all five of those within an hour?
If the honest answer is no, the gap review tells you which ones are missing and what it takes to close them. Thirty minutes, no charge.
If it happens

You have 60 days from discovery to notify.

Nobody buys compliance because of the penalty tiers. They buy it for the phone call at 6am when the front desk can't log in.

Walking in with the evidence
Day 1
Counsel has the risk analysis and dated remediation records the same morning.
Week 1
Working logs answer what was accessed, when, and by whom.
Week 2
Notification decided and made, on time.
A two week process.
Walking in with nothing
Day 1
Counsel asks for documentation on day one. It does not exist yet.
Weeks 1–4
Reconstructing a risk analysis under deadline, at your attorney's hourly rate.
Weeks 5–8
Still establishing what was accessed, while also trying to see patients.
A two month reconstruction.
What we do when it happens: call 406-924-3731. It doesn't go into a ticket queue. We run the technical response, preserve evidence, work alongside your counsel and handle the notification timeline. We can't give you legal advice and won't pretend otherwise but we can make sure your attorney isn't starting from a blank page.
For practices

Where the risk actually sits in a practice.

Not in the EHR. In the six places below, which is where we look first. Your exposure is a patient complaint, a payer audit, an insurance renewal, or a breach that becomes public in a small community.

Front desk workflows and screen visibility
Staff turnover, and the terminations never removed from systems
Personal devices used for on call
Remote access for your EHR vendor and your billing company
The fax and scanning workflow nobody has looked at in a decade
Every vendor that walks through the building
MIPS attestation
If you attest to having completed a Security Risk Analysis, that attestation is a statement to a federal program. It's checkable. We keep the analysis current and dated so the attestation is true when you make it.
Payer and hospital questionnaires
Forward them. We complete them from the evidence we already maintain, usually within a few business days rather than the few weeks it takes to assemble from scratch.
For business associates

You're directly liable in your own right.

Your risk shows up as a lost contract before it shows up as an enforcement action. Health systems are tightening vendor review, and the question is no longer whether you'll sign a BAA.

What a prospective client asks for
A current risk analysis
Your own, not your client's
Training records
Names, dates, completion
An incident response plan
Written, and tested
Subcontractor agreements
For anyone downstream of you
Vendors who can't produce these are quietly dropped from the approved list, and nobody tells them why.
3 days
Returning the questionnaire in three days instead of three months wins deals. Compliance evidence stops being overhead and becomes a sales asset.
Book the gap review
The Madison River near Ennis, Montana
What it costs

Choose by what is happening to you.

Most practices know which of these two sentences is true of them. The table underneath is the detail, if you want it.

Start here
Nobody is asking yet, and you want that to stay true.
You need a current risk analysis, the policies behind it and training you can prove — kept current, so the next questionnaire is a forwarding job rather than a project.
$350 / month
Compliance Foundations
For real audit exposure
Someone is already asking, or is about to.
A payer audit, an OCR inquiry, a hospital contract or an insurer who wants evidence. You want the quarterly review, and someone who answers the questionnaire for you.
$560 / month
Full Compliance Management
Foundations
Full management
A current Security Risk Analysis
Annually and on change
Annually and on change
Policies written to your systems
Yes
Yes
Training tracked by name
Yes
Yes
BAAs calendared with renewal dates
Yes
Yes
The evidence file, kept current
Yes
Yes
Quarterly review with your leadership
—
Yes
We answer questionnaires and payer audits for you
—
Yes
Remediation work itself
Scoped and quoted separately
Scoped and quoted separately
Next step

Find out what an auditor would find ahead of time.

The gap review is thirty minutes and free. You will know where you stand and what it would take to close it.

01
Been sent a questionnaire?
Forward it to us and we'll tell you what it actually requires.
02
Not sure when your last risk analysis was?
That answer is usually the whole conversation.
03
Need the day to day IT as well?
Healthcare Managed IT is the other half, priced separately.
Signed BAA before we touch anything. If we're not the right fit, we'll say so on the call.
“Great company to work with. Any issues we have had they have addressed quickly.”
Kevin F. | Montana dental practice
★★★★★ 5.0 on Google and Birdeye · Read the reviews
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
We reply within one business day.